Friday, January 30, 2009

UAC Fix in Windows 7 Creates Security Hole, Blogger Says

A change that Microsoft made in Windows 7 to improve its controversial User Account Control security feature has left the new OS less secure, according to a blogger who follows Microsoft closely.
Microsoft made the change to UAC, a feature that was introduced with Windows Vista, to make it more user-friendly in Windows 7. But the change has allowed for "a simple but ingenious override" that disables UAC without any action on the part of the user, according to the I Started Something blog written by longtime Microsoft watcher Long Zheng.
Microsoft added UAC to Vista in an effort to improve its security and give people who are the primary users of a PC more control over its applications and settings. UAC prevents users without administrative privileges from making unauthorized changes to a system. But because of how it was set up in Vista, UAC sometimes prevents even authorized users from being able to access applications and features they should normally have access to.
It does this through a series of screen prompts that ask the user to verify privileges, and it may require them to type in a password to perform a task. This can interrupt people's workflow, even during some mundane tasks, unless they are set as Local Administrator. The UAC prompts became so problematic that Apple even spoofed them in a television commercial, and Microsoft vowed to improve the feature in Windows 7.
Windows 7 is still in beta and not expected to ship until late this year or early next. Microsoft released the beta earlier this month and outlined the changes to UAC on the Engineering Windows 7 blog.
The changes revise the UAC's default setting, and that is where the security risk lies, according to Zheng.
As he explained in his post, UAC's default setting in Windows 7 is to "Notify me only when programs try to make changes to my computer" and "Don't notify me when I make changes to Windows settings."
UAC distinguishes between a third-party program and a Windows setting with a security certification, and control-panel items are signed with this certificate so they don't issue prompts if a user changes system settings, he wrote.
However, in Windows 7, changing UAC is considered a "change to Windows settings," according to Zheng. This, coupled with the new default UAC security level, means a user will not be prompted if changes are made to UAC, including if it was disabled.
With a few keyboard shortcuts and some code, Zheng said he can disable UAC remotely without the end-user knowing.
"With the help of my developer side-kick Rafael Rivera, we came up with a fully functional proof-of-concept in VBScript (would be just as easy in C++ EXE) to do that -- emulate a few keyboard inputs -- without prompting UAC," he wrote. "You can download and try it out for yourself here, but bear in mind it actually does disable UAC."
Zheng also posted what he said is a workaround for the problem on his blog.
Microsoft said on Friday through its public relations firm that it was looking into the problem and did not have an immediate comment.

Second Life Profitable Despite Interface Woes

In exclusive interviews with The Industry Standard, Linden Lab's two top executives have confirmed that the company is still profitable and Second Life is continuing to grow users and expand its enterprise services. However, Linden Lab founder and chair Philip Rosedale and CEO Mark Kingdon admitted that the in-world experience still takes too long for new users to master, an issue that will require significant amounts of technological work to rectify.
The two executives spoke to the Standard at the company's headquarters in San Francisco earlier this month (see Interview with Linden Lab CEO Mark Kingdon and Interview with Second Life creator Philip Rosedale for transcripts).
Kingdon acknowledged an "incredible hype phase" that had introduced lots of people to the potential of virtual worlds, but had also put the spotlight on many negative aspects. He said that the company was in a "comfortable place" in terms of growth in active users, usage hours, and Second Life uptime.
Rosedale said that Second Life had moved beyond an emerging application for technology-savvy users. "There is a lot more diversity in use, demographics and behavior in Second Life today than there was, say, at the end of 2003," he said.
Kingdon echoed this assessment. "I think the world has gotten its head around the fact that virtual worlds are here to stay," Kingdon said. "There is a very compelling set of activities that virtual worlds are incredibly powerful for. They erase geographies, they allow for a type of interaction that you can't get in the real world and they bring with them really interesting economic and business opportunities for users."
Kingdon pointed to several localization projects for countries in Europe, Asia, and South America, and cited in-world training and remote meetings as compelling activities for companies. Both he and Rosedale portrayed Second Life as a competitor to enterprise video conferencing, which they believe is unable to match Second Life's ability to make people feel comfortable interacting with other remote users.
As for competing virtual worlds, Kingdon said he and his team tried to keep abreast of trends, but declined to name any current competitors.
Discussing Google's closure of Lively last year, Kingdon said it was a "natural" outcome, considering Google's focus and the state of the economy. "I don't think that Lively's departure is an invalidation of the market. I think, it's just recognition that, yeah, there is promise [and] a lot of hard work," Kingdon explained. "Google made the right decision and said, 'We need to kind of stick to our knitting in this economic downturn, in this climate, and focus our resources on some of our core properties,' which is quite natural."
Rosedale said There.com had some "unique" aspects and had effectively targeted certain vertical markets, but called it "substantially less interesting" in terms of the content that users can create. "The demographic is tighter, narrower, less diverse," he stated.
Linden Lab's CEO said that despite the recession, the company remained profitable. "We have not felt the same in world economic turmoil that the real world has faced," Kingdon said, noting that Second Life was an affordable entertainment alternative to activities such as going to a movie. "Dollar for dollar, it's high-value entertainment for the casual user," he said.
On the enterprise side, he and Rosedale described uptime improvements and new products, including a hosted service and a behind-the-firewall service nicknamed "Nebraska" aimed at companies with stronger security needs.
However, the Linden executives said that a lot of work remained to be done in terms of making the service easier to use. Rosedale singled out search, the user interface and new user orientation as needing major improvements. "We need to collapse the orientation experience on learning the interface down to a 30-minute timeframe," he declared. "We're not there yet."
Rosedale went on to describe the current interface as "overwhelming."
He said, "the basic UI of the software also needs to change. It has too many pixels," referring to the buttons, numbers, and other data presented to users on the screen. "They're all kind of demanding your attention -- your [Linden] dollar balance, your inventory window, all the buttons on the bottom bar, chat and text that are visible in the window, that's asking something of you, blue pop-ups that are coming up."
Rosedale said that while the work required to make the interface less complex was significant, it would have a huge impact on the adoption rate of virtual worlds. Currently, only 15% of the people who tried out Second Life continued to use the virtual world. "I'd like to triple that number," he stated.
Nevertheless, progress has been made in terms of making the technology more appealing to new users. Kingdon described how the old Second Life registration process -- a seven-page form which he likened to a mortgage application -- had been streamlined. "We've very substantially shortened the registration flow," he said. "We shortened it in July to one page and saw a very substantial increase in registration completions."
Kingdon added that the company has also implemented better email management techniques to increase activations, and was also paying attention to SEO, in order to help users get to helpful Second Life resources via Web search engines.

The Web 2.0 'Conversation' Is Really a Shouting Match

Web 2.0 wonks like to gush about how the Internet these days is all about "joining the conversation." Lately, though, it's been more like a shouting match.
Today's example: The fall of Michael Arrington.
As Rodrigues & Urlocker (the Captain & Tennille of InfoWorld bloggers) have also noted, Michael Arrington is hanging up his keds at TechCrunch -- at least through the month of February, if not longer. The reason? He's sick of all the haters.
On his most recent blog post, Arrington said death threats he'd received last summer, coupled with recently being spat upon at a conference a few days ago, were key factors in his decision. Hey, nobody should have to endure stuff like that just for expressing their opinions, whether you agree with them or not.
But in true Arrington form, he couldn't just leave it at that. In an interview with the Wall Street Journal, he implicitly blamed popular blog sites Valleywag (now part of Gawker) and AllThingsD -- led by poppa bear Walt Mossberg of the Wall Street Journal and BoomTown's Kara Swisher -- for daring to question his ethics and (thus) inciting the haters. Quoth Mr. TechCrunch:
"Whoever is the top blog will get attacked by everyone else and that'll just be the way it is," Mr. Arrington said. "We really need to think about, the community of bloggers, if we're going to continue to slay our own for competitive reasons."
Apply your own cliche here -- glass houses, stones, heat, kitchen, pot, kettle, black, etc. Just about any of them work. And who exactly anointed TechCrunch "top blog"? I must have missed that press release.
Still, you have to give TechCrunch its due. In a few short years, it's grown from one guy spouting his opinions on startups to one of the most popular (and feared) news sites on the Net. It has broken some real stories -- like Google's acquisition of YouTube -- before the mainstream media had even heard of "viral video." Its reach is impressive. Even the Washington Post deigned to syndicate TechCrunch.
On the other hand, there's still too much of one guy spouting his opinions masquerading as real journalism for my taste. The site seems willing to publish any rumor, which means it's wrong a lot of the time. It's become a running joke that every week or so TechCrunch will post a story saying Google is going to acquire some company, and when it doesn't happen, post a second story saying they walked away from the deal. Rightly or wrongly, questions about Arrington's relationship to the companies he writes about continue to dog him.
(Note: This blog is sometimes guilty of much of the above. But then, I make no claims to be a news source. We're all snark all the time here in Cringeville.)
My real point is, Arrington's right: It has gotten nastier out there. Maybe it's always been this way, and the flame wars that used to be confined to alt.geek.whatever on Usenet have now exploded across the Net.
I see it here in the comments to this blog. All I need to do is pick the right topic -- anti- or pro-Microsoft, Apple, Linux; Scientology vs "Anonymous"; science vs faith; and anything that touches on politics -- and the anonymous posters come out with guns blazing. It's like pushing the flame button; it's automatic.
So far, the worst thing that's happened is people unsubscribing from the e-mail newsletter -- no death threats or spittle yet. But it seems like it's only a matter of time before that kind of thing starts happening to more of us.
Has the Net gotten nastier? Can "love keep us together"? E-mail me direct: cringe@infoworld.com.

AMD Set to Release DDR3-Capable Processors

Advanced Micro Devices will soon introduce processors that are capable of supporting DDR3 memory, earlier than the company had anticipated.
The company in the next few weeks will launch new processors targeted at desktops that will include DDR3-capable memory controllers, said John Taylor, an AMD spokesman.
Taylor declined comment on specific processors being launched, though a leaked road map suggests the launch of new Phenom II and triple-core processors.
The support for DDR3 memory comes earlier than anticipated. Late last year the company said it aimed to add DDR3-capable Phenom II processors by the middle of 2009, but could push that up depending on factors including pricing of the memory.
Compared to current DDR2-capable processors, the new DDR3-capable chips will allow information from the memory to be communicated to a CPU faster, which translates to better PC performance. To run DDR3-capable processors, the company will introduce the AM3 socket for motherboards.
"The people who want the latest and greatest will want to use DDR3 memory," Taylor said.
AMD's decision to switch to DDR3 memory is to make CPUs faster so it can effectively compete with Intel in the high-end PC and server markets, said Dean McCarron, president of Mercury Research, a market analysis firm.
"When we make changes in PC architecture, it is because it's either faster or cheaper," said McCarron. For AMD, the decision was technical rather than financial, but the enhanced competitiveness could yield a financial benefit to AMD in the long run, McCarron said.
Intel's Core i7 processor for gaming systems, launched in November, already supports DDR3 memory. Intel is also adding DDR3 support to chips for portable products like laptops.
However, given AMD's inherent price advantage compared to Intel's products, price-sensitive buyers may initially oppose the high prices of DDR3 memory modules, McCarron said. As of early January, a 1GB DDR3 memory module running at 1333MHz was priced at $35, versus $12 to $14 per unit for a 1GB DDR2 unit.
"This is completely normal for technology. As the volume ramps [DDR3 memory prices] will come down," McCarron said.
Motherboard companies like Asus have already announced AM3-compatible motherboards, setting the stage for AMD to launch its new DDR3-capable processors, which could include new Phenom II processors. The new CPUs will include a DDR2- and DDR3-capable memory controller, allowing it to work with older motherboards with DDR2 memory.
AMD earlier this year launched new quad-core Phenom II processors, which the company called its "highest-performing" CPUs to date. Aimed at high-end desktop PCs, the chips ran at speeds of up to 3GHz and included 8MB of cache.
However, the Phenom II chips are capable of even faster clock speeds under certain circumstances. For example, the processors have been overclocked to run at speeds of up to 6.5GHz on liquid-cooled systems and up to 4GHz on air-cooled systems.
AMD remains on track to transition to DDR3 memory support for servers with the Maranello platform in 2010, Taylor said. The Maranello platform includes the six-core Sao Paulo and 12-core Magny-Cours chips.

Friday, January 23, 2009

Windows 7 Security Features Get Tough

Two years after Windows Vista debuted, many companies have yet to upgrade. And in many instances their reluctance to migrate to Vista stemmed from concern about security.
Microsoft hass responded with its latest operating system, Windows 7, currently in public beta and expected to ship later this year. In Windows 7, new security features have been added, popular features expanded, and familiar features enhanced. Here's a look at a dozen or so security improvements that we expect will convince even the most recalcitrant corporate clients to upgrade.
Improved Migration Tools
Microsoft says that Windows 7 will be faster and easier to roll out across an enterprise than previous OS migrations were. Much of the credit for the anticipated improvement goes to new tools such as Dynamic Driver Provisioning, Multicast Multiple Stream Transfer, and Virtual Desktop Infrastructure.
With Dynamic Driver Provisioning, drivers are stored centrally, separate from images. IT professionals can arrange for installation by individual BIOS sets or by the Plug and Play IDs of a PC's hardware. Microsoft says that reducing the number of unnecessary drivers installed will help avoid potential conflicts and will accelerate installation. With Windows 7, as with Windows Vista, IT professionals can update system images offline, and even maintain a library of images that includes different drivers, packages, features, and software updates.
Rolling out any particular image across the entire network--or even installing individual images on desktops--is faster in Windows 7, thanks to the new Multicast Multiple Stream Transfer feature. Instead of individually connecting to each client, deployment servers "broadcast" the images across the network to multiple clients simultaneously.
Virtual Desktop Infrastructure (VDI), another desktop deployment model, allows users to access their desktops remotely, thereby centralizing data, applications, and operating systems. VDI supports Windows Aero, Windows Media Player 11 video, multiple-monitor configurations, and microphone support for voice over IP (VoIP) and speech recognition. New Easy Print technology permits VDI users to print to local printers. But use of VDI requires a special license from Microsoft, and doesn't offer the full functionality of an installed operating system.
Protecting Corporate Assets
Once the OS is installed, organizations may protect their assets with authentication for log-in. Windows Vista included drivers for fingerprint scanners, and Windows 7 makes such devices easier for IT professionals and end-users to set up, configure, and manage. Windows 7 extends the smart card support offered in Windows Vista by automatically installing the drivers required to support smart cards and smart card readers, without administrative permission.
IT professionals may further protect the contents of their Windows 7 volumes with BitLocker, Microsoft's whole-disk encryption system. Windows Vista users have to repartition their hard drive to create the required hidden boot partition, but Windows 7 creates that partition automatically when BitLocker is enabled. In Windows Vista, IT professionals must use a unique recovery key for each protected volume. But Windows 7 extends the Data Recovery Agent (DRA) to include all encrypted volumes; as a result, only one encryption key is needed on any BitLocker-encrypted Windows machine.
BitLocker To Go is a new feature that lets users share BitLocker-protected files with users running Windows Vista and Windows XP. The BitLocker To Go desktop reader provides simple, read-only access to the protected files on non-BitLocker-protected systems. To unlock the protected files, the user must provide the appropriate password (or smart-card credentials).
Application Control
Windows 7 also introduces AppLocker , an enhancement to Group Policy settings that lets organizations specify which versions of which applications users have permission to run. For example, a rule might allow users to install Adobe Acrobat Reader version 9.0 or later, but it might block them from installing legacy versions without specific authorization. AppLocker contains a rule-generation wizard to make the process of creating policies much easier, and it includes automatic rule making for building a custom white list.
System Restore, first introduced in Windows ME, gets a much needed update in Windows 7. First, System Restore displays a list of specific files that will be removed or added at each restore point. Second, restore points are now available in backups, giving IT professionals and others a greater list of options over a longer period of time.
The Action Center is a new, integrated Control Panel feature that gives Windows 7 users a central spot for locating tasks and common notifications under a single icon. The Action Center includes alerts and configuration settings for several existing features, including the Security Center; Problem, Reports, and Solutions; Windows Defender; Windows Update; Diagnostics; Network Access Protection; Backup and Restore; Recovery; and User Account Control. Popup alerts are gone in Windows 7, replaced by a new task tray icon (a flag with an X) that provides streamlined access to the problem directly or to the Action Center for more information.
Perhaps the most famous and most annoying form of Windows Vista notification comes from the User Account Control (UAC) feature, which flashes administrative warnings whenever you need to configure a system setting. In Vista the choices are stark: Endure the messages, or turn off UAC. In Windows 7, you have additional options. A slider bar configures the appropriate notification level for your computer, and by default UAC will notify you only when programs try to make changes to your PC.
Better Performance
Windows Defender, Microsoft's antispyware product, gains a much-needed performance enhancement in Windows 7. But Microsoft has removed the Software Explorer tool, asserting that the utility doesn't affect spyware detection or removal. That might be true, but Software Explorer would allow you to see what programs and processes are running, including ones that you may not know about or want. Perhaps Microsoft will reverse this decision by the final build.
Another new feature of Windows 7 is the Windows Filtering Platform (WFP), a group of APIs and system services that allow third party vendors to tap further into Windows' native firewall resources, thereby improving system performance. Microsoft stresses that WFP is a development platform and not a firewall in itself, but WFP does address a few of Windows Vista's firewall problems.
In Vista, Microsoft introduced the concept of profiles for different types of network connections--home, network, public and domain. This, however, bound corporate IT professionals whenever a remote user accessed their corporate VPN, because the firewall was already set as either "home" or "public," and corporate network settings could not be applied later. Windows 7 and WFP in particular permit multiple firewall policies, so IT professionals can maintain a single set of rules for remote clients and for clients that are physically connected to their networks. Windows 7 also supports Domain Name System Security Extensions (DNSSEC), newly established protocols that give organizations greater confidence that DNS records are not being spoofed.
Features for Mobile Users
Windows 7 has two enhancements designed for mobile users. With DirectAccess, mobile workers can connect to their corporate network any time they have Internet access--without needing a VPN. DirectAccess updates Group Policy settings and distributes software updates whenever the mobile computer has Internet connectivity, whether the user is logged on to a corporate network or not. This ensures that mobile users stay up-to-date with company policies. And with BranchCache, a copy of data accessed from an intranet Web site or from a file server is cached locally within the branch office. Remote users can use BranchCache to access shared data rather than using a connection back to headquarters.
Windows 7 also makes enhancements to event auditing. Regulatory and business requirements are easier to fulfill through management of audit configurations, monitoring of changes made by specific people or groups, and more-granular reporting. For example, Windows 7 reports why someone was granted or denied access to specific information.

Study: Spam Is Getting More Malicious

Spam, especially junk e-mails with malicious links or attachments, continues to be a huge IT headache. Spammers are also getting more creative in their attempts to find victims, utilizing popular sites such as Facebook and Twitter, according to a report from UK-based security firm Sophos this week.
The consultancy published its latest spam trend report and said new figures reveal that spam is still causing problems for computer users. In the fourth quarter of 2008, Sophos research found one in every 256 e-mails contained a dangerous attachment in October. In November, that figure improved to one in 384. December saw a huge decline: Just one in every 2000 e-mails contained a spam. Graham Cluley, senior technology consultant at Sophos, said it is possible the drop-off may be related to the shut down of the McColo Corp., a Web-hosting firm that security experts believe was responsible for three-quarters of the world's spam.
"It's hard to say exactly what can be causing this," said Cluley. "Certainly that is possible."
Numbers for January have not been assessed yet and Cluley said it is too early to determine if the drop off in spam levels has continued, or if spam is now back at levels seen in earlier months. What is clear, said Cluley, is that more spam is malicious in nature now and often designed to infect users' computers via sophisticated malware attachments or a link to malicious or infected websites, in order to steal sensitive information. Cluley also said social networking venues, such as Facebook and Twitter, are now the hot targets for spammers.
"Spammers really took to using sites like Facebook and Twitter as a vehicle for their spam antics during the last three months of 2008," he said. "Cybercriminals have cottoned onto the fact that social networking users can be more easily fooled into clicking on a link that appears to have come from a trusted Facebook friend, than if it arrived as an unsolicited email in their inbox. The notorious Nigerian 419 scammers have even evolved, masquerading as Facebook friends in order to trick unwary users into parting with valuable sensitive and financial information. Ultimately, while users are still falling for these scams, the fraudsters will continue. And while the authorities are making great progress, everyone must take steps to ensure they don't fall victim."
Death to Spam?
The report also referenced a 2004 prediction by Bill Gates that spam would be a thing of the past in 2 years.
"The rumors of spam's death have been greatly exaggerated over the years the threat remains alive and kicking despite increased legal action against spammers, the occasional takedown of Internet companies which assist the cybercriminals, and constantly improving anti-spam software," said Cluley. "Many IT professionals cast doubt on Bill Gates' assertion back in 2004, deeming the timeframe of his pledge to be unrealistic. Although the latest stats show that the proportion of spam relayed per country may have decreased year-on-year, spammers have turned to more creative, not to mention devious, methods to ensure their messages reach as many unsuspecting computer users as possible."
And the Spam King Crown Goes to...
Between October and December 2008, the United States was responsible for most of the world's spam, according to Sophos. China was in the second spot and Russia was third. Sophos officials pointed to Canada, Japan and France as countries that have made progress in spam prevention. All three, considered "serial offenders" five years ago, are no longer present in the list of spam reprobates.
"Although there's no denying that some countries have significantly reduced their contribution to the spam epidemic over the past five years, the United States still holds the crown," said Cluley. "Though its spam contribution has significantly decreased since Bill Gates' proclamation, falling from almost half of all spam relayed at the end of 2004, to 21.3 percent by the end of 2007, and now resting at 19.8 percent, this shows there's certainly no quick fix."

Mac BitTorrent Users Warned of Trojan

Mac users ill-advised enough to search for pirated copies of Apple's iWork 09 software could find themselves on the wrong end of an unpleasant and crafty new Trojan.
According to Mac security software company Intego, which has put out the alert, OSX.Trojan.iServices.A allows users to install a fully-working copy of iWork 09 as normal, but only at the price of letting malware bury into OS X using a rogue install add-on.
As with a lot of PC Trojans, the immediate purpose of the software is simply to compromise the OS X system comprehensively enough to allow for the downloading of further malware from a remote host, another way of saying that the user could be opening themselves up to more or less anything the writers fancy putting on the system.
According to Intego, this is no theoretical infection that will affect only a handful of people, having been downloaded at least 20,000 times using the BitTottent file sharing system in recent days.
Apple's iWork software, which would normally set the user back around £70 ($79), is an all-purpose program that includes document, spreadsheet and presentation features. The latest version that is being used as a lure on BitTorrent distributions sites, will be sought after by users of pirated software having been released only weeks ago.
The company stands to benefit from the alert of course - it is currently virtually the only Mac-only software security outfit. The big-name anti-virus products sold for Macs tend to be spin-offs from much more lucrative PC protection programs.
"Intego VirusBarrier X4 and X5 with virus definitions dated January 22, 2009 or later protect against this Trojan horse," the company said in a release.
The number of Trojans affecting Mac users is on a modest upward curve, helped the company said during a recent and separate Mac Trojan outbreak, by the tendency of some Apple users to see their computers as above Windows-like security woes. The number of companies that actively track malware targeting Apple users is also proportionately smaller than for Windows PCs.